Page 1 of 1

Notice to delete keyhelp_login_data password file after copying it

Posted: Thu 26. Oct 2023, 11:26
by shoulders
At the beginning of the installation you have to set your password or use the one already there, which is fine. Because I was using Putty I was alble to copy this password with my mouse.

At the end of the installation you get the following message telling you this file has all of your details in it.

Code: Select all

You will find your login credentials in the file:
/root/keyhelp_login_data_2023-10-25_15-56-06
Improvement
  • At the beginning of the installation, where you enter your password, display a note telling the user that a file will be created at the end with all of those details in it.
  • At the end of the installation, Tell the user to get a copy of the keyhelp_login_data_2023-10-25_15-56-06 file and then delete it of the server. Leaving it is a security risk. Maybe put in red.
  • Additionally, advise the user they can also delete the install file install_keyhelp.sh as it is no longer needed

Re: Notice to delete keyhelp_login_data password file after copying it

Posted: Thu 26. Oct 2023, 11:44
by Florian
Hello,

the file is located in the /root folder. No one besides root is able to enter this folder. If so you have got severer problems.

Re: Notice to delete keyhelp_login_data password file after copying it

Posted: Thu 26. Oct 2023, 11:56
by shoulders
LastPass got hacked because the developer had a Plex server on his network, better to be safer than sorry.

Re: Notice to delete keyhelp_login_data password file after copying it

Posted: Thu 26. Oct 2023, 11:58
by 24unix
shoulders wrote: Thu 26. Oct 2023, 11:56 LastPass got hacked because the developer had a Plex server on his network, better to be safer than sorry.
Unrelated. The file is only accessible by root.
When you are already root you got the power to overwrite all passwords stored there. Nothing gained from that file.